CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36365 | CVE-2008-6248 | Candidate | Cross-site scripting (XSS) vulnerability in all.php in Galatolo WebManager 1.3a and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter. | Assigned (20090223) | None (candidate not yet proposed) | View | |
101901 | CVE-2017-5081 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170102) | None (candidate not yet proposed) | View | |
36621 | CVE-2008-6504 | Candidate | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a u0023 representation for the # character. | Assigned (20090323) | None (candidate not yet proposed) | View | |
102157 | CVE-2017-5337 | Candidate | Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate. | Assigned (20170110) | None (candidate not yet proposed) | View | |
36877 | CVE-2008-6760 | Candidate | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. | Assigned (20090428) | None (candidate not yet proposed) | View |
Page 1091 of 20943, showing 5 records out of 104715 total, starting on record 5451, ending on 5455